MigrationTool 3.3 Info and Guide

Attached is the documentation, please review it before use the new version.

If you dont have internet access from your MT you can use the offline update provided here as well. Remember to unzip the file first.

Note for the first time we introduced support for ikev1 IPSEC L2L within Cisco ASA configurations. Please take this in consideration when use it and please report anything you consider is wrong or can be enhanced, let's use the power of this community to improve the tool.

New Features [MT-157] - Added Multi Edit on Nat Rules [MT-174] - Add support for Regions under Objects [MT-220] - Add CISCO VPN L2L support (First version) [MT-223] - Zones. Remove or Set Interfaces in the zones by selecting them [MT-275] - Rename IPSecTunnel, IKE Gateway and Zones with a single click [MT-276] - Attach IKE V1 and IKE V2 Profiles to the selected IKE Gateways [MT-167] - Created new Tab for VPN. Added support for IPSec Tunnels, GlobalProtect and NetworkProfiles

Improvements

[MT-181] - Reduced by 52x the time to import a Palo Alto Networks configuration. [MT-216] - Added the option to Enable/Disable Rule Filters [MT-219] - NAT. SRX and Screenos. Support for Rules where a SNAT and DNAT its applied. [MT-252] - SNIPPETS. Added support for Applications-Groups, Address, Services and Wildfire Profiles. Multiple entries are supported inside some snippets. Check Documentation. [MT-253] - Virtual Router Editor. Added a Checkbox to add all the Interfaces with a single click [MT-269] - Consolidation. Added the field Action [MT-270] - Policy Filters: Clear button clear all Filters if any is selected and closes the view automatically

Have fun !!

Updated with a change in the OUTPUT Api Manager behavior, now all is EDIT instead of SET when SubAtomic is selected.

@WCoats, I did figure out how to install this version. They don't make it that readily apparent in the installation instructions, but what you have to do is install the base version of the Migration tool *first* to create the virtual machine. The file that is attached to this article is just a patch file that will upgrade you to version 3.3.

Once you have the VM downloaded and installed in VMWare workstation, ESXi, or whatever hypervisor you're using; log into the web-based GUI. There is an option in the main dashboard to upgrade the version of the tool. Upload the .bundle file in the "browse" window and it should upgrade the software. I went from 3.1, to 3.2, to 3.3 personally, so IDK for sure if you can go from 3.1 directly to 3.3.

Tipically to get latest update you have to click from the main view after login on the Updates tab and click the Update button. In the case your MT can't reach internet then you can use the bundle files. But only on this case, use always the Update button if you dont any restriction to go to Internet.

Has the Update server been decommisioned? For three weeks I tried to update my 3.1 and no luck. Finally I saw this post and updated to 3.3.9 with the bundle. Now I hit the green "Update" button and I still get nothing. I saw one resident engineer had 3.3.14 on his MT. My dns settings are fime. My MT server can ping www.yahoo.com and can resolve conversionupdates.paloaltonetworks.com but I get no response from Ping.

I'm trying to confirm if I could use MT3.3 to migrate firewalls into a PA-5220, PAN-OS 8.0.7. I understand that I will need a device with those characteristics but MT3.3 only have 5000 and 7000 series. Is it 5220 included in 5000 or has to be 5200 series as expected?